Kernel API Functions 内核API函数

函数名称INT 2ehNtdll.Nt*Ntdll.Zw*Ntoskrnl.Nt*Ntoskrnl.Zw*1NtAcceptConnectPort 0x0000N/AN/A2NtAccessCheck 0x0001N/AN/A3NtAccessCheckAndAuditAlarm 0x0002N/A4NtAccessCheckByType 0x0003N/AN/A5NtAccessCheckByTypeAndAuditAlarm0x0004N/AN/A6NtAccessCheckByTypeResultList 0x0005N/AN/A7NtAccessCheckByTypeResultListAndAuditAlarm; 0x0006N/AN/A8NtAccessCheckByTypeResultListAndAuditAlarmByHandle; 0x0007N/AN/A9NtAddAtom 0x0008N/A10NtAdjustGroupsToken 0x0009N/AN/A11NtAdjustPrivilegesToken; 0x000A12NtAlertResumeThread 0x000BN/AN/A13NtAlertThread 0x000CN/A14NtAllocateLocallyUniqueld 0x000DN/A15NtAllocateUserPhysicalPages0x000EN/AN/A16NtAllocateUuids0x000FN/A17NtAllocateVirtualMemory0x001018NtAreMappedFilesTheSame0x0011N/AN/A19NtAssignProcessToJobObject0x0012N/AN/A20NtBuildNumberN/AN/AN/AN/A21NtCallbackReturn0x0013N/AN/A22NtCancelDeviceWakeupRequest0x0016N/AN/A23NtCancelloFile0x0014N/A24NtCancelTimer0x0015N/A25NtClearEvent0x0017N/A26NtClose0x001827NtCloseObjectAuditAlarm0x0019N/A28NtCompleteConnectPort0x001AN/AN/A29NtConnectPort0x001B30NtContinue0x001CN/AN/A31NtCreateChannel0x00F1N/AN/A32NtCreateDirectoryObject0x001DN/A33NtCreateEvent0x001E34NtCreateEventPair0x001FN/AN/A35NtCreateFile0x002036NtCreateloCompletion0x0021N/AN/A37NtCreateJobObject0x0022N/AN/A38NtCreateKey0x0023N/A39NtCreateMailslotFile0x0024N/AN/A40NtCreateMutant0x0025N/AN/A41NtCreateNamedPipeFile0x0026N/AN/A42NtCreatePagingFile0x0027N/AN/A43NtCreatePort0x0028N/AN/A44NtCreateProcess0x0029N/AN/A45NtCreateProfile0x002AN/AN/A46NtCreateSection0x002B47NtCreateSemaphore0x002CN/AN/A48NtCreateSymbolicLinkObject0x002DN/A49NtCreateThread0x002EN/AN/A50NtCreateTimer0x002FN/A51NtCreateToken0x0030N/AN/A52NtCreateWaitablePort0x0031N/AN/A53NtCurrentTebN/AN/AN/AN/A54NtDelayExecution0x0032N/AN/A55NtDeleteAtom0x0033N/A56NtDeleteFile0x003457NtDeleteKey0x0035N/A58NtDeleteObjectAuditAlarm0x0036N/AN/A59NtDeleteValueKey0x0037N/A60NtDeviceloControlFile0x003861NtDisplayString0x0039N/A62NtDuplicateObject0x003A63NtDuplicateToken0x003B64NtEnumerateKey0x003CN/A65NtEnumerateValueKey0x003DN/A66NtExtendSection0x003EN/AN/A67NtFilterToken0x003FN/AN/A68NtFindAtom0x0040N/A69NtFlushBuffersFile0x0041N/AN/A70NtFlushlnstructionCache0x0042N/A71NtFlushKey0x0043N/A72NtFlushVirtualMemory0x0044N/A73NtFlushWriteBuffer0x0045N/AN/A74NtFreeUserPhysicalPages0x0046N/AN/A75NtFreeVirtualMemory0x004776NtFsControlFile0x004877NtGetContextThread0x0049N/AN/A78NtGetDevicePowerState0x004AN/AN/A79NtGetPlugPlayEvent0x004BN/AN/A80NtGetTickCount0x004CN/AN/A81NtGetWriteWatch0x004DN/AN/A82NtGlobalFlagN/AN/AN/AN/A83NtlmpersonateAnonymousToken0x004EN/AN/A84NtlmpersonateClIEntOfPort0x004FN/AN/A85NtlmpersonateThread0x0050N/AN/A86NtlnitializeRegistry0x0051N/AN/A87NtlnitiatePowerAction0x0052N/A88NtlsSystemResumeAutomatic0x0053N/AN/A89NtListenChannel0x00F2N/AN/A90NtListenPort0x0054N/AN/A91NtLoadDriver0x0055N/A92NtLoadKey0x0056N/A93NtLoadKey20x0057N/AN/A94NtLockFile0x0058N/A95NtLockVirtualMemory0x0059N/AN/A96NtMakeTemporaryObject0x005AN/A97NtMapUserPhysicalPages0x005BN/AN/A98NtMapUserPhysicalPagesScatter0x005CN/AN/A99NtMapViewOf Section0x005D100NtNotifyChangeDirectoryFile0x005EN/A101NtNotifyChangeKey0x005FN/A102NtNotifyChangeMultipleKeys0x0060N/AN/A103NtOpenChannel0x00F3N/AN/A104NtOpenDirectoryObject0x0061N/A105NtOpenEvent0x0062N/A106NtOpenEventPair0x0063N/AN/A107NtOpenFile0x0064108NtOpenloCompletion0x0065N/AN/A109NtOpenJobObject0x0066N/AN/A110NtOpenKey0x0067N/A111NtOpenMutant0x0068N/AN/A112NtOpenObjectAuditAlarm0x0069N/AN/A113NtOpenProcess0x006A114NtOpenProcessToken0x006B115NtOpenSection0x006CN/A116NtOpenSemaphore0x006DN/AN/A117NtOpenSymbolicLinkObject0x006EN/A118NtOpenThread0x006FN/A119NtOpenThreadToken0x0070N/A120NtOpenTimer0x0071N/A121NtPlugPlayControl0x0072N/AN/A122NtPowerlnformation0x0073N/A123NtPrivilegeCheck0x0074N/AN/A124NtPrivilegedServiceAuditAlarm0x0075N/AN/A125NtPrivilegeObjectAuditAlarm0x0076N/AN/A126NtProtectVirtualMemory0x0077N/AN/A127NtPulseEvent0x0078N/A128NtQueryAttributesFile0x007AN/AN/A129NtQueryDefaultLocale0x007BN/A130NtQueryDefaultUILanguage0x007CN/A131NtQueryDirectoryFile0x007D132NtQueryDirectoryObject0x007EN/A133NtQueryEaFile0x007F134NtQueryEvent0x0080N/AN/A135NtQueryFullAttributesFile0x0081N/AN/A136NtQuerylnformationAtom0x0079N/A137NtQuerylnformationFile0x0082138NtQuerylnformationJobObject0x0083N/AN/A139NtQuerylnformationPort0x0085N/AN/A140NtQuerylnformationProcess0x0086141NtQuerylnformationThread0x0087N/AN/A142NtQuerylnformationToken0x0088143NtQuerylnstallUILanguage0x0089N/A144NtQuerylntervalProfile0x008AN/AN/A145NtQueryIoCompletion0x0084N/AN/A146NtQueryKey0x008BN/A147NtQueryMultipleValueKey0x008CN/AN/A148NtQueryMutant0x008DN/AN/A149NtQueryObject0x008EN/A150NtQueryOpenSubKeys0x008FN/AN/A151NtQueryPerformanceCounter0x0090N/AN/A152NtQueryQuotalnformationFile0x0091N/A153NtQuerySection0x0092N/A154NtQuerySecurityObject0x0093156NtQuerySemaphore0x0094N/AN/A157NtQuerySymbolicLinkObject0x0095N/A158NtQuerySystemEnvironment Value0x0096N/AN/A159NtQuerySystemlnformation0x0097160NtQuerySystemTime0x0098N/AN/A161NtQuery Timer0x0099N/AN/A162NtQueryTimerResolution0x009AN/AN/A163NtQueryValueKey0x009BN/A164NtQuery VirtualMemory0x009CN/AN/A165NtQuery VolumelnformationFile0x009D166NtQueueApcThread0x009EN/AN/A167NtRaiseException0x009FN/AN/A168NtRaiseHardError0x00A0N/AN/A169NtReadFile0x00Al170NtReadFileScatter0x00A2N/AN/A171NtReadRequestData0x00A3N/AN/A172NtReadVirtualMemory0x00A4N/AN/A173NtRegisterThreadTerminatePort0x00A5N/AN/A174NtReleaseMutant0x00A6N/AN/A175NtReleaseSemaphore0x00A7N/AN/A176NtRemoveloCompletion0x00A8N/AN/A177NtReplaceKey0x00A9N/A178NtReplyPort0x00AAN/AN/A179NtReplyWaitReceivePort0x00ABN/AN/A180NtReplyWaitReceivePortEx0x00ACN/AN/A181NtReplyWaitReplyPort0x00ADN/AN/A182NtReplyWaitSendChannel0x00F4N/AN/A183NtRequestDeviceWakeup0x00AEN/AN/A184NtRequestPort0x00AFN/A185NtRequestWaitReplyPort0x00B0186NtRequestWakeupLatency0x00BlN/AN/A187NtResetEvent0x00B2N/A188NtResetWriteWatch0x00B3N/AN/A189NtRestoreKey0x00B4N/A190NtResumeThread0x00B5N/AN/A191NtSaveKey0x00B6N/A192NtSaveMergedKeys0x00B7N/AN/A193NtSecureConnectPort0x00B8N/AN/A194NtSendWaitReplyChannel0x00F5N/AN/A195NtSetContextChannel0x00F6N/AN/A196NtSetContextThread0x00BAN/AN/A197NtSetDefaultHardErrorPort0x00BBN/AN/A198NtSetDefaultLocale0x00BCN/A199NtSetDefaultUILanguage0x00BDN/A200NtSetEaFile0x00BE201NtSetEvent0x00BF202NtSetHighEventPair0x00C0N/AN/A203NtSetHighWaitLowEventPair0x00ClN/AN/A204NtSetlnformationFile0x00C2205NtSetlnformationJobObject0x00C3N/AN/A206NtSetlnformationKey0x00C4N/AN/A207NtSetlnformationObject0x00C5N/A208NtSetlnformationProcess0x00C6209NtSetlnformationThread0x00c7210NtSetlnformationToken0x00C8N/AN/A211NtSetlntervalProfile0x00C9N/AN/A212NtSetloCompletion0x00B9N/AN/A213NtSetLdtEntries0x00CAN/AN/A214NtSetLowEventPair0x00CBN/AN/A215NtSetLowWaitHighEventPair0x00CCN/AN/A216NtSetQuotalnformationFile0x00CDN/A217NtSetSecurityObject0x00CE218NtSetSystemEnvironment Value0x00CFN/AN/A219NtSetSystemlnformation0x00D0N/A220NtSetSystemPowerState0x00DlN/AN/A221NtSetSystemTime0x00D2N/A222NtSetThreadExecutionState0x00D3N/AN/A223NtSetTimer0x00D4N/A224NtSetTimerResolution0x00D5N/AN/A225NtSetUuidSeed0x00D6N/AN/A226NtSetValueKey0x00D7N/A227NtSetVolumelnformationFile0x00D8228NtShutdownSystem0x00D9N/AN/A229NtSignalAndWaitForSingleObject0x00DAN/AN/A230NtStartProfile0x00DBN/AN/A231NtStopProfile0x00DCN/AN/A232NtSuspendThread0x00DDN/AN/A233NtSystemDebugControl0x00DEN/AN/A234NtTerminateJobObject0x00DFN/AN/A235NtTerminateProcess0x00E0N/A236NtTerminateThread0x00ElN/AN/A237NtTestAlert0x00E2N/AN/A238NtUnloadDriver0x00E3N/A239NtUnloadKey0x00E4N/A240NtUnlockFile0x00E5N/A241NtUnlockVirtualMemory0x00E6N/AN/A242NtUnmapViewOfSection0x00E7N/A243NtVdmControl0x00E8N/A244NtWaitForMultipleObjects0x00E9N/A245NtWaitForSingleObject0x00EA246NtWaitHighEventPair0x00EBN/AN/A247NtWaitLowEventPair0x00ECN/AN/A248NtWriteFile0x00ED249NtWriteFileGather0x00EEN/AN/A250NtWriteRequestData0x00EFN/AN/A251NtWriteVirtualMemory0x00F0N/AN/A252NtYieldExecution0x00F7N/A

    推荐阅读